TeamPCP Supply Chain Campaign: Update 006 - CERT-EU Confirms European Commission Cloud Breach, Sportradar Details Emerge, and Mandiant Quantifies Campaign at 1,000+ SaaS Environments, (Fri, Apr 3rd)
2026-04-04T07:23:48Z•ee9b0635e69052ba06b458ce1edd09e5a16a13eb32801a6d0f6c0fcf51ba0b1d
AstraZenecaCERT-EUCVE-2025-30208DPRK-attributionDatabricksEuropean-CommissionMandiantMercor-AISaaSSportradarTeamPCPVitecloud-breachpost-compromise-enumerationransomwaresoftware-supply-chainsupply-chain
What happened
SANS ISC updates on the TeamPCP supply-chain campaign (Update 006, covering Apr 1–3, 2026) report widespread compromise of SaaS/cloud environments. CERT-EU confirmed a breach of the European Commission cloud; Sportradar-related details emerged; Mandiant estimates the campaign impacted 1,000+ SaaS environments. Earlier updates document confirmed victims (Mercor AI), post-compromise cloud enumeration (Wiz), alleged DPRK involvement in an Axios compromise, Databricks and AstraZeneca incidents, and dual ransomware operations. Also noted: active exploitation attempts against exposed Vite installs (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- ee9b0635e69052ba06b458ce1edd09e5a16a13eb32801a6d0f6c0fcf51ba0b1d
- Enrichment time
- 2026-04-04T07:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.